Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 8Objective 4

Web Application Firewall (WAF) CASENET Practice Questions (Page 4)

Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
11concepts

Questions 16–20

  1. 16application · medium

    A WAF administrator notices a large number of requests in the logs with the following pattern: /product?id=1%27%20OR%20%271%27%3D%271. The requests come from a single IP address and are increasing over time. What does this pattern indicate, and what should the administrator do?

    Select an answer first
  2. 17application · medium

    A WAF log shows multiple requests to /login.aspx with varying 'User-Agent' strings, each containing a different SQL injection payload. The requests come from different IP addresses but within a short time window. What does this pattern most likely indicate?

    Select an answer first
  3. 18application · medium

    A security architect is designing a defense-in-depth strategy for a public-facing .NET web application. The application already has input validation and parameterized queries. Which additional control would provide the most value at the network perimeter?

    Select an answer first
  4. 19expert · hard

    A company has a WAF in front of a .NET application. The WAF uses a negative security model with a rule that blocks any request containing the string '<script>'. Recently, legitimate users have been unable to submit a form that includes a text area for user comments, because some comments contain HTML tags. The security team wants to maintain protection against XSS while reducing false positives. What is the best approach?

    Select an answer first
  5. 20application · medium

    An attacker is attempting to bypass a WAF by sending a request like: /search?q=1%27%20UNION%20SELECT%20password%20FROM%20users--&q=test. The WAF only inspects the first 'q' parameter. Which bypass technique is being used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.